From October, Windows 11 will turn on one of its strongest kernel-level defenses by default on eligible PCs. Microsoft says Memory Integrity, a security feature that has existed since Windows 10, will start rolling out through regular Windows Updates from October 2026. It targets devices where the feature was never manually switched on. If you game on an older machine, it’s worth knowing before the update lands.

What Memory Integrity actually does
Memory Integrity, also called Hypervisor-Protected Code Integrity or HVCI, is part of Virtualization-based Security (VBS). It checks kernel-mode code and drivers against a list of trusted software before letting them run. The check happens inside the hardware-based hypervisor, isolated from the rest of Windows. In plain terms, it makes it harder for malware to plant a rootkit. It also raises the bar for attacks that hijack a vulnerable driver to take control of your PC. The feature already runs by default on clean Windows 11 installs and on Secured-core PCs. October’s change extends it to machines that were upgraded from older Windows versions, or that shipped with it turned off.
In its own announcement, Microsoft framed the change as removing friction rather than adding a new requirement:
“Windows quality updates will begin enabling memory integrity protection on eligible devices. If not already enabled, these updates will also enable VBS, helping make additional security capabilities available and reflecting our commitment to making Windows secure by design and secure by default.”
Which PCs are eligible
Microsoft says Windows will automatically evaluate a device’s readiness before flipping the switch. It checks hardware capability, driver compatibility, and performance. Reported requirements based on Microsoft’s documentation include an 8th-generation Intel Core processor or newer, AMD Zen 2 or newer, or Qualcomm Snapdragon 8180 or newer. It also calls for at least 8GB of RAM, a 64GB SSD, and virtualization enabled in firmware. Machines that fall short, or that run unconfirmed drivers, should be skipped by the automatic rollout.
Microsoft says anyone who already turned Memory Integrity off, manually or through an administrator policy, won’t have that choice overridden. The rollout only targets PCs where the feature is off simply because nobody ever turned it on.
The gaming performance question
The tradeoff that has PC gamers paying attention is performance. VBS and HVCI add overhead every time code crosses between user mode and kernel mode. That overhead shows up most in games that lean hard on the CPU. Tom’s Hardware lab-tested VBS and HVCI on Intel and AMD desktop chips when Microsoft first pushed these protections by default on new PCs. It measured an average gaming performance loss in the 4 to 6 percent range across its test suite. Some individual titles lost up to 8 percent. Older CPUs and older drivers tend to feel it more. Microsoft has previously acknowledged the tradeoff, telling users they can temporarily disable the protections while gaming, with the caveat that security drops while it’s off.
This update reaches PCs automatically, without a prompt. Anyone chasing every last frame on an older CPU may see their benchmark numbers shift after October’s Patch Tuesday update, with no obvious explanation unless they know where to look.
How to check or change it yourself
You don’t have to wait for Microsoft to decide for you. Here’s how to check whether Memory Integrity is on, or turn it off if the rollout hurts your gaming performance:
- Open the
Windows Securityapp from the Start menu - Select Device security, then Core isolation details
- Toggle Memory integrity on or off, then restart your PC for the change to take effect
Microsoft’s rollout begins with the October 2026 Patch Tuesday update, on October 13. Review this setting on an older gaming PC beforehand, rather than letting a quality update decide for you.
